Access
Install a connector
Run the connector inside your network so Zaysa can reach private databases and servers.
About 5 minutes
A connector is a small agent that runs on a Linux machine inside your network. It opens a connection out to Zaysa, so you never open a port to the internet, and it is how your team reaches private databases and servers through Zaysa. One connector serves everything in its network: you add databases and servers to it later, without running anything again.
This page installs a connector on a Linux machine. To read a Kubernetes cluster, install the connector inside the cluster instead: see Connect a Kubernetes cluster.
Before you start
- Any plan. Free includes one connector, Pro five and Business as many as you need.
- A Linux machine inside the network you want to reach, with
curland root orsudo. It can be small: the connector is one container. Docker is installed for you if it is missing. - The machine can open outbound HTTPS (port 443) to
zaysa.io. No inbound port is needed.
Add the connector
Open Connectors
In the left sidebar, open Beam → Connectors and click Add connector (1).
Choose what it will reach and name it
(1) Pick what the connector will reach first: Database, VM (SSH), Kubernetes or OpenShift. (2) Name it after where it runs, for example
prod-vpcoroffice-network. (3) Click Create.Copy the install command
Zaysa shows the one-line command for this connector. Click Copy (1).
It has this shape. Yours already contains your connector’s values, so there is nothing to fill in:
Install commandcurl -fsSL https://zaysa.io/api/beam/install | BEAM_TOKEN=bmc_<your-token> BEAM_CONNECTOR_ID=<connector-id> BEAM_COMMAND_PUBKEY=<command-key> shTreat the command like a password
TheBEAM_TOKENin it lets a machine register as this connector. Paste it only on the machine you chose, and do not share it in chat or tickets. If it leaks, delete the connector and add a new one.Run it on your machine
Open a terminal on the Linux machine, paste the command and press Enter. Keep the Zaysa window open: it says Waiting for “office-network” to dial in… until the connector connects. The installer ends like this:
Linux machine✓ container running beam-connector connecting... online 🎉 Done — your connector is live. Back in Zaysa it shows online. This one connector is a gateway for its whole network: add as many databases as you want (managed or self-hosted) — no re-run.
Check it worked
Back in Zaysa, the connector’s card shows Online (1), when it was last seen and its version. From the same card you add what it should reach: Add database, Add SSH or Add K8s.
What the installer does
| On your machine | Details |
|---|---|
| Docker | Only if no container runtime is found. It uses the system package manager (dnf, yum, apt, zypper or apk) and uses Docker’s own install script only if that fails. Podman is used if it is already there. |
| Token file | /etc/beam/token, readable only by the connector. The token is not passed to the container as an environment variable. |
| Policy file | /etc/beam/policy.env. It limits where the connector may connect (by default your private networks and the machine itself) and what it may do. The connector enforces it on every request, whoever sends it. Re-running the installer keeps your edits. |
| The connector | The zaysahq/beam-connector image, pinned to an exact version and digest. For a database connector it runs as a non-root user with all Linux capabilities dropped. |
| A service | On machines with systemd, beam-connector.service, so it starts again after a reboot. Otherwise a container that restarts on its own. |
VM (SSH) connectors
Update the connector
Automatic updates are off. To update, run the same command again, or the same command without the token: the installer reuses the token already on the machine, so the connector keeps its identity and everything attached to it.
If something goes wrong
“installed, but it has NOT connected yet”
The container is running but cannot reach Zaysa. Check its log, then check that the machine can open outbound HTTPS to zaysa.io:
sudo docker logs beam-connector
curl -sSI https://zaysa.io | head -1“the control plane rejected this token (401)”
The token is no longer valid. Delete the connector in Zaysa, add a new one and run its new command.
“couldn't auto-install Docker”
Install Docker with your system’s package manager, for example sudo dnf install -y docker, then run the command again.
Remove a connector
- In Zaysa, click the bin icon on the connector’s card. Zaysa stops accepting it at once.
- On the machine, stop it and remove its files:
sudo systemctl disable --now beam-connector
sudo rm -f /etc/systemd/system/beam-connector.service
sudo docker rm -f beam-connector
sudo rm -rf /etc/beam